Google paused its open-source bug bounty program on October 1 after AI-generated spam overwhelmed security teams. The company said, "We are temporarily no longer accepting OSS VRP product vulnerability submissions." This freeze aims to fix the submission process, with an official update expected to arrive in the first quarter 2027.

Google has paused product vulnerability submissions for its Open Source Software Vulnerability Reward Program (OSS VRP) after a flood of invalid, AI-generated reports overwhelmed security engineers and repository maintainers. The company announced the operational freeze in a post on X, directing security researchers toward its other active reward initiatives. Google stated that it will use the downtime to restructure the submission framework, with an official progress update slated for the first quarter of 2027.

What changes and what stays active

The suspension took effect immediately on October 1, though Google outlined specific exceptions to avoid shutting down critical disclosure channels. One of them is that the pause does not affect valid product vulnerability filings logged before October 1. The freeze applies specifically to product vulnerability reports; supply chain disclosures submitted under the OSS VRP remain open. Certain product vulnerability reports tied to Google Cloud repositories that directly impact Cloud products may still be accepted through the separate Google Cloud VRP.

Read Google VRP’s post

PSA for open-source bug huntersWe are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. Previously, Linux maintainers reported being completely flooded by bogus Common Vulnerabilities and Exposures (CVE) filings after automated AI hunters drove recorded vulnerabilities to a record high of 2,000 per release. The influx forced the Linux project to drop support for older network drivers. Chipmaker Intel also recently froze its bug bounty program, which offered payouts reaching $100,000 per flaw. While Intel did not cite synthetic submissions as the official cause, industry analysts widely attribute the shutdown to identical AI spam bottlenecks.

End of Article

Latest Mobiles

View All

Samsung Galaxy A08 4G

₹18,499

Ai+ Nova 2 Neo 5G

₹17,999

Nothing Phone 4b

₹31,999

Nothing Phone 4a

₹36,999

Vivo S2 FE 5G

OPPO K14 Lite 4G

₹18,999

Motorola A300

₹1,370

Lava Bold N4 Pro 5G

₹15,999

Moto G77 Power 5G

₹26,799

Ai+ Nova 2 Power 5G

₹16,999

OPPO K14 Plus 5G

₹25,999

OnePlus N6 Lite 4G

₹16,999

Realme 16 Pro Harry Potter Edition

₹62,999

Lava Virat Curve 5G

₹23,999

Realme Narzo 90X

₹19,499

iQOO Z11xa 5G

₹28,999

Apple iPhone Duo

₹2,99,900

Apple iPhone 18 Pro

₹1,64,900

Philips S7221 5G

₹22,499

Poco M7 Plus

₹17,999

iQOO Z10 Lite

₹16,997

Vivo Y21 5G

₹20,999